Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ScanStar ("Processor") and the business owner using the ScanStar platform ("Controller"). This DPA applies where ScanStar processes personal data on behalf of the Controller in the course of providing the Services.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Portuguese data protection law.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

"Controller" means the business owner who determines the purposes and means of processing Personal Data collected through the ScanStar platform.

"Processor" means ScanStar, which processes Personal Data on behalf of the Controller.

"Data Subject" means the individual whose Personal Data is being processed — in this context, the end customers of the Controller who interact with ScanStar plates, capture pages, or StarPages.

"Sub-processor" means any third party engaged by ScanStar to process Personal Data on behalf of the Controller.

2. Scope and Purpose

ScanStar processes Personal Data on behalf of the Controller solely for the purpose of providing the Services described in the Terms of Service, including:

  • Storing customer contact information submitted through ScanStar capture pages
  • Recording scan events and analytics associated with ScanStar plates
  • Displaying and managing review data synced from third-party platforms
  • Providing CRM, analytics, and reporting features within the platform

ScanStar shall not process Personal Data for any purpose other than as instructed by the Controller or as required by applicable law.

3. Controller Obligations

The Controller agrees to:

  • Ensure that there is a lawful basis for collecting and processing the Personal Data of their customers, including obtaining appropriate consent where required
  • Provide Data Subjects with clear and transparent information about how their data will be used, including through the ScanStar capture page
  • Comply with all applicable data protection laws, including the GDPR, in relation to Personal Data collected through the Services
  • Not instruct ScanStar to process Personal Data in a manner that would violate applicable law

4. Processor Obligations

ScanStar agrees to:

  • Process Personal Data only on documented instructions from the Controller, including as set out in this DPA and the Terms of Service
  • Ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations
  • Implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, destruction, or alteration
  • Not engage any Sub-processor without informing the Controller and ensuring the Sub-processor is bound by equivalent data protection obligations
  • Assist the Controller in responding to requests from Data Subjects exercising their rights under the GDPR, to the extent possible given the nature of the processing
  • Notify the Controller without undue delay upon becoming aware of a Personal Data breach affecting data processed under this DPA
  • At the choice of the Controller, delete or return all Personal Data upon termination of the Services, unless retention is required by applicable law

5. Sub-processors

The Controller authorises ScanStar to engage the following Sub-processors to assist in providing the Services:

Sub-processor Purpose Location
Supabase Database and authentication USA
Stripe Payment processing USA
Resend Transactional email delivery USA
Shopify Online store and checkout Canada / Global

 

ScanStar will inform the Controller of any intended changes to this list of Sub-processors, giving the Controller the opportunity to object. ScanStar ensures that all Sub-processors are bound by data protection obligations equivalent to those set out in this DPA.

6. International Data Transfers

Where Personal Data is transferred outside the European Economic Area, ScanStar will ensure that such transfers are made in accordance with applicable data protection law, including through the use of Standard Contractual Clauses issued by the European Commission or other recognised transfer mechanisms.

7. Data Subject Rights

ScanStar will assist the Controller in fulfilling its obligations to respond to Data Subject requests, including requests to access, correct, delete, or port Personal Data. Where a Data Subject contacts ScanStar directly, ScanStar will redirect the request to the Controller without undue delay.

8. Security

ScanStar shall implement and maintain appropriate technical and organisational security measures to protect Personal Data, including:

  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorised personnel only
  • Regular security assessments of infrastructure and systems
  • Use of reputable third-party infrastructure providers with their own security certifications

9. Data Breach Notification

In the event of a Personal Data breach, ScanStar will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, where feasible. The notification will include the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences of the breach, and the measures taken or proposed to address it.

10. Audit Rights

The Controller may request information from ScanStar to demonstrate compliance with this DPA. ScanStar will provide the Controller with all information reasonably necessary to demonstrate compliance with its obligations under this DPA and applicable data protection law.

11. Term and Termination

This DPA remains in effect for as long as ScanStar processes Personal Data on behalf of the Controller. Upon termination of the Terms of Service, ScanStar will, at the Controller's request, delete or return all Personal Data processed under this DPA within 30 days, unless retention is required by applicable law.

12. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. ScanStar is not liable for any breach of this DPA caused by the Controller's failure to fulfil its own obligations as Controller under applicable data protection law.

13. Governing Law

This DPA is governed by the laws of Portugal and the GDPR. Any disputes arising under this DPA shall be subject to the jurisdiction of the courts of Portugal.

14. Contact

For any questions regarding this DPA or to exercise your rights, contact us at hello@scanstar.co.